1. Home
  2. Jobs
  3. United Arab Emirates
  4. Dubai
  5. Chief Information Security Officer
  6. Chief Information Security Officer (CISO)
myZoi Financial Inclusion Technologies Ltd logoMF

Chief Information Security Officer (CISO)

Dubai, United Arab EmiratesFull-time1 day ago

Chief Information Security Officer

TheRole

Lead the organisation's cybersecurity and information security programme, ensuring the confidentiality, integrity,andavailabilityofinformationassetsacrossaregulatedfinancialservicesenvironment.Defineand execute security strategy, own and manage cyber risk within Board-approved appetite, and maintain regulatory compliance within a cloud-native payments and stored value facility (SVF) operation.
Theroleadvisesandrecommendsonsecurityrisk,withindependentauthoritytoescalateunresolvedriskto the CTO, CEO, and Board Risk Committee. Operates within an approved annual security budget; spend proposals require cost-benefit justification and are prioritised within the allocated envelope.
KeyResponsibilities

SecurityStrategy&Governance

  • Defineandmaintainamulti-yearcybersecuritystrategyalignedwithbusinessgrowth,riskappetite, and regulatory obligations.
  • Establishandmaintaintheinformationsecuritypolicyframework,reviewedatleastannually.
  • Maintainthecyberriskregisterandownthesecuritymaturityroadmapagainstarecognisedcontrol framework (NIST CSF, CIS Controls, or ISO 27001).
  • Ownthesecurityriskacceptanceandexceptionregister.
  • Providesecurityleadershipandadvisorytoexecutivemanagementandregulatorystakeholders.

Threat&VulnerabilityManagement

  • Directtheenterprisevulnerabilitymanagementprogramme,includingscanning,risk-based prioritisation, and remediation SLA enforcement.
  • Overseethepenetrationtestingprogrammeandensurefindingsareremediatedandretestedwithin defined timelines.
  • Maintainthreatintelligencecapabilityrelevanttofinancialservicesandpayments,andtranslateit into detection and control improvements.

SecurityOperations

  • Overseesecuritymonitoring,detection,andresponsecapabilitiesincludingSIEM,EDR/XDR,and SOC operations (internal or MSSP-managed).
  • Own incident responseend to end: maintain and test playbooks, run tabletop exercises, lead containmentandrecovery,andcoordinateregulatorynotificationwithinapplicabledeadlines.
  • ManageidentityandaccessgovernanceincludingRBACdesign,privilegedaccessmanagement, joiner/mover/leaver controls, and periodic access recertification.
  • Defineandenforcedatalosspreventionanddataclassificationstandardsacrossallplatforms.

Regulatory&Compliance(FirstLine)

  • MaintainoperationalcompliancewithPCIDSS,CBUAEtechnologyandinformationsecurityrisk requirements, UAE Information Assurance standards, and applicable payment scheme obligations.
  • Serveasprimarysecurityliaisontoexternalauditors,QSAs,andregulatoryexaminers.
  • Ensuresecuritycontrolsaredocumented,evidenced,tested,andaudit-readyatalltimes.
  • Trackandclosesecurity-relatedauditandexaminationfindingswithinagreedtimelines.

DataProtection&Privacy

  • ImplementandmaintainsecuritycontrolssupportingUAEPDPLandapplicablecross-borderdata transfer obligations, in coordination with Legal and the Data Protection Officer.
  • Supportprivacyimpactassessmentsanddatabreachassessmentandnotification.

SecurityArchitecture

  • Providesecurityinputtosystemdesign,changerequests,andnewinitiatives,andapprovesecurity architecture standards and baseline configurations.
  • Embedsecurity-by-designintheengineeringlifecycle,includingsecureSDLC,codereview, dependency scanning, secrets management, and CI/CD pipeline controls.
  • MaintaincloudsecurityposturestandardsfortheAWSestate.

CyberResilience

  • Ensurecyberscenariosarerepresentedinbusinesscontinuityanddisasterrecoveryplanningand testing.
  • Validatebackupintegrity,immutability,andrecoverycapabilityagainstdestructiveattack scenarios.

Third-PartySecurity

  • Assessthesecuritypostureofprospectiveandexistingthirdpartiesandoutsourcedproviders, proportionate to criticality and data exposure.
  • DefinesecurityrequirementsforvendorcontractsincoordinationwithLegalandProcurement.
  • Managesecurityserviceproviders(MSSP,penetrationtestingfirms,consultants)againstdefined SLAs.

People&Capability

  • Leadanddevelopthesecurityteam.
  • Drivesecurityawarenessthroughtrainingprogrammesandphishingsimulations.
  • Fosteraconstructivesecurityculturethatenablessafeescalationandreporting.

Reporting

  • Monthlysecurityreporting totheCTO.
  • StandingquarterlysecurityandcyberriskupdatetotheBoardRisk Committee.
  • ImmediatenotificationofmaterialincidentstotheCTO,CEO,andChiefRisk Officer.

Requirements

Experience

  • 10+yearsofprogressiveexperienceininformationsecurity,withatleast5yearsinaleadership role.
  • Demonstratedexperienceinaregulatedfinancialservicesenvironment(banking,payments, fintech, or SVF).
  • Hands-onexperiencewiththePCIDSScompliancelifecycleinapaymentenvironment.
  • Proventrackrecordofleadingincidentresponseduringlivesecurityevents.
  • ExperiencemanagingSOCoperations(internalorMSSP)includingSIEM,EDR/XDR,andthreat intelligence.
  • Strongunderstandingofcloudsecurity(AWSpreferred),containerandKubernetessecurity,and API security.
  • Experiencewithregulatoryframeworks:CBUAEtechnologyandinformationsecurityrisk circulars, UAE IA, or equivalent.
  • DemonstratedabilitytocommunicatesecurityrisktoexecutiveandBoard-levelaudiences.
  • Experiencemanagingthird-partysecurityvendorsandserviceproviders.
  • Experiencebuildinganddevelopingsecurityteams.
  • Demonstratedabilitytodeliversecurityoutcomeswithinconstrainedbudgets,prioritisingrisk reduction per unit of spend.

Leadership&SoftSkills

  • Strongstrategicthinkingwithabilitytotranslateriskintobusiness language.
  • Abilitytoinfluencewithoutauthorityacrossengineering,product,andbusinessteams.
  • Clearcommunicatorwhocanbriefexecutivesandregulatorsunderpressure.
  • CollaborativeapproachwithEngineering,Operations,GRC,andbusinessstakeholders.
  • Comfortableinfast-paced,scalingenvironmentswithevolvingpriorities.

Qualifications

  • Bachelor'sdegreeinComputerScience,Cybersecurity,InformationTechnology,orarelatedfield, or equivalent professional experience.
  • Industrycertificationsrequired(oneormore):CISSP,CISM,CISA,orISO27001LeadAuditor.
  • Additionalcertificationsvalued:PCIP,OSCP,CCSK,CRISC,AWSSecuritySpecialty.

TechnologyEnvironment

AWS(Lambda,ECS,EKS,RDS,CloudFront,WAF),Kubernetes,Kafka,PostgreSQL,Java/SpringBoot, React, React Native, Datadog, Microsoft 365/Entra ID, Terraform.

AdditionalConditions

  • Participationinanon-callescalationrotaforsecurityincidents.
  • Availabilityoutsidestandardhoursduringliveincidentsandmajorchangeevents.
  • Appointmentsubjecttoenhancedbackgroundscreeningappropriatetoaregulatedfinancial services control function.